web-ctf
Installation
SKILL.md
Web CTF
Goal: solve web-application CTF tasks with professional methodology, curated high-signal references, and reproducible evidence.
When this skill applies
- HTTP apps, APIs, browser clients, templates, auth flows, file uploads, SSRF, XSS, SQLi, SSTI, XXE, deserialization, request smuggling, GraphQL/WebSocket APIs, or prototype pollution
- tasks requiring endpoint mapping, parameter discovery, exploit chaining, or stateful session testing
Operating model
- Classify the dominant artifact, primitive, or objective.
- Load the closest
offensive-techniquesmethodology before selecting tools. - Load the closest curated reference for the dominant primitive before touching deep topic banks.
- Use
sql-injection.mdas the deep bank when the focused SQLi reference is too shallow for the current edge case. - Choose the smallest tool chain that can produce a validation signal.
- Record the exact proof path and stop once the objective is reproducible.